ATT&CKReferencesIntezer Doki July 20

Intezer Doki July 20

Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareDoki

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

T1036.005
Match Legitimate Resource Name or Location
MalwareDoki

Doki has disguised a file as a Linux kernel module.

T1041
Exfiltration Over C2 Channel
MalwareDoki

Doki has used Ngrok to establish C2 and exfiltrate data.

T1057
Process Discovery
MalwareDoki

Doki has searched for the current process’s PID.

T1059.004
Unix Shell
MalwareDoki

Doki has executed shell scripts with /bin/sh.

T1071.001
Web Protocols
MalwareDoki

Doki has communicated with C2 over HTTPS.

T1083
File and Directory Discovery
MalwareDoki

Doki has resolved the path of a process PID to use as a script argument.

T1102
Web Service
MalwareDoki

Doki has used the dogechain.info API to generate a C2 address.

T1105
Ingress Tool Transfer
MalwareDoki

Doki has downloaded scripts from C2.

T1133
External Remote Services
MalwareDoki

Doki was executed through an open Docker daemon API port.

T1568.002
Domain Generation Algorithms
MalwareDoki

Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains.

T1573.002
Asymmetric Cryptography
MalwareDoki

Doki has used the embedTLS library for network communications.

T1610
Deploy Container
MalwareDoki

Doki was run through a deployed container.

T1611
Escape to Host
MalwareDoki

Doki’s container was configured to bind the host root directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.